MEDIUM 5.8 GitHub
CVE-2026-73607
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
### Summary
`/api/storage/getOutlineStorage` is registered with `CheckAuth` only and performs no authorization of any kind. Given a document identifier it returns that document's stored outline state, regardless of the document's publish tier.
The two write endpoints for the same data, `setOutlineStorage` and `removeOutlineStorage`, both carry `CheckAdminRole` and `CheckReadonly`. Only the read path is unguarded.
### Details
**Routes.** `kernel/api/router.go:103` on master, `:108` on the dev
Affected Products
- go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2
References
- https://github.com/advisories/GHSA-53fp-9jmv-227g
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-53fp-9jmv-227g
- https://nvd.nist.gov/vuln/detail/CVE-2026-73607
- https://github.com/siyuan-note/siyuan/releases/tag/v3.8.0
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-01 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.